Supabase · Supabase Terms of Service · View original document ↗

Aggregated Data as Supabase Intellectual Property

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 343 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Supabase Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Supabase can use anonymized and aggregated data derived from your data and usage to improve and analyze its services, and this derived data is treated as Supabase's own intellectual property.

This analysis describes what Supabase's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

Even though Supabase does not claim ownership of your raw customer data, it retains rights to insights and analytics derived from that data, which is a common but material practice in cloud service agreements that customers should factor into their own privacy disclosures.

Interpretive note: The adequacy of anonymization is not defined in the agreement; whether derived data meets GDPR or CCPA deidentification standards depends on implementation details not disclosed in this document.

Recent Activity

This document changed recently

Medium May 6, 2026

The relocation of Supabase's legal entity from Delaware to Singapore may affect which jurisdiction's courts and laws apply to disputes, potentially impacting your ability to pursue claims in US courts and changing which consumer protection laws govern your relationship. The requirement to explicitly click 'I Accept' rather than accepting through sign-up or service use clarifies consent but does not substantively change the agreement's terms. The new section on AI-powered tools discloses that Supabase may use AI chatbots for customer support; review that section to understand how such tools may process your inquiries.

View change record →

Consumer impact (what this means for users)

Data about how you and your users interact with Supabase's platform can be aggregated and used by Supabase indefinitely as its own intellectual property, even after your subscription ends. Customers with strict data minimization obligations under GDPR or sector-specific regulations should assess whether this derivation is disclosed in their own privacy notices.

How other platforms handle this

MetaMask Medium

We may share your personal information with our affiliates, meaning entities that control, are controlled by, or are under common control with Consensys. We also share information with service providers who assist in operating our services, subject to confidentiality obligations.

Ledger Medium

At Ledger, earning and maintaining our users' trust is a top priority. That's why we are deeply committed not only to protecting your privacy and securing your personal data, but also to being fully transparent about how we handle it.

Target Medium

RedCard. We share information with our financial partners to operate the Target RedCard program.

See all platforms with this clause type →

Monitoring

Supabase has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
"Aggregated Data" means data and information related to or derived from Customer Data or Customer's use of the Services that is used by Supabase in an aggregate and anonymized manner, including to compile statistical and performance information related to the Services. [...] "Supabase IP" means the Services, the Documentation, and any and all intellectual property provided to Customer or any Authorized User in connection with the foregoing. For the avoidance of doubt, Supabase IP includes Aggregated Data and any information, data, or other content derived from Supabase's provision of the Services but does not include Customer Data.

— Excerpt from Supabase's Supabase Terms of Service

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

REGULATORY LANDSCAPE: The Aggregated Data provision implicates GDPR Article 5 (data minimization and purpose limitation) and Recital 26 (anonymization standards), as well as CCPA definitions of deidentified data. The adequacy of Supabase's anonymization methodology is not described in this agreement; customers acting as data controllers bear responsibility for ensuring downstream processing by processors meets applicable standards. The DPA referenced in the agreement should address this processing basis. GOVERNANCE EXPOSURE: Medium. Classifying derived data as Supabase IP is standard in cloud service agreements, but the scope of 'derived from Customer Data' is broad and could encompass behavioral patterns, query structures, or usage metrics that indirectly reveal customer or end-user information if re-identification risk is not adequately managed. JURISDICTION FLAGS: GDPR's standard for anonymization is high; data that fails the anonymization test under GDPR remains personal data subject to full regulatory obligations. California's CCPA defines deidentified data with specific technical and contractual safeguards. Healthcare customers subject to HIPAA should assess whether derived data could constitute de-identified PHI under the Safe Harbor or Expert Determination methods. CONTRACT AND VENDOR IMPLICATIONS: The DPA should be reviewed to confirm whether Aggregated Data processing is addressed as a permitted purpose or reserved right, and whether customers receive any transparency about how aggregation and anonymization are implemented technically. The IP classification of Aggregated Data means customers cannot later claim ownership or seek deletion of this derived data. COMPLIANCE CONSIDERATIONS: Customers should update their own privacy notices to disclose that their cloud service provider may derive aggregated analytics from their data; review the DPA for anonymization standards and audit rights; and assess whether the Aggregated Data carve-out is compatible with their data processing agreements with their own customers.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Monitor free for 14 days

Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    FTC oversees data practices including aggregation and deidentification claims that may constitute unfair or deceptive practices if anonymization is inadequate
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
DMA
European Union
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US
VPPA
United States Federal

Provision details

Document information
Document
Supabase Terms of Service
Entity
Supabase
Document last updated
May 5, 2026
Tracking information
First tracked
May 10, 2026
Last verified
May 10, 2026
Record ID
CA-P-009139
Document ID
CA-D-00681
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
b05f1426ea2945724132049d0ec22530b3eef85e9a34314efce12ed1efa3c1f0
Analysis generated
May 10, 2026 15:04 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Supabase
Document: Supabase Terms of Service
Record ID: CA-P-009139
Captured: 2026-05-10 15:04:09 UTC
SHA-256: b05f1426ea294572…
URL: https://conductatlas.com/platform/supabase/supabase-terms-of-service/aggregated-data-as-supabase-intellectual-property/
Accessed: June 27, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Related Analysis

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Compliance free trial

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Supabase's Aggregated Data as Supabase Intellectual Property clause do?

Even though Supabase does not claim ownership of your raw customer data, it retains rights to insights and analytics derived from that data, which is a common but material practice in cloud service agreements that customers should factor into their own privacy disclosures.

How does this clause affect you?

Data about how you and your users interact with Supabase's platform can be aggregated and used by Supabase indefinitely as its own intellectual property, even after your subscription ends. Customers with strict data minimization obligations under GDPR or sector-specific regulations should assess whether this derivation is disclosed in their own privacy notices.

Is ConductAtlas affiliated with Supabase?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Supabase.